Vulnerability Description
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jose4J Project | Jose4J | < 0.9.5 |
Related Weaknesses (CWE)
References
- https://bitbucket.org/b_c/jose4j/issues/220/vuln-zip-bomb-attackExploitIssue TrackingMitigation
- https://bitbucket.org/b_c/jose4j/issues/220/vuln-zip-bomb-attackExploitIssue TrackingMitigation
FAQ
What is CVE-2024-29371?
CVE-2024-29371 is a vulnerability with a CVSS score of 7.5 (HIGH). In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token ...
How severe is CVE-2024-29371?
CVE-2024-29371 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-29371?
Check the references section above for vendor advisories and patch information. Affected products include: Jose4J Project Jose4J.